CVE-2026-35225: Codesys Ethernetip

High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.

An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.

Affected products

  • Codesys Codesys Ethernetip: from 1.0.0.0, before 4.9.0.0 (fixed in 4.9.0.0)

Published 2026-04-23. Last modified 2026-06-17.